Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

618 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.6)0.69%—Microsoft Azure Logic Apps7/8/20267/8/2026
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
AnalizadaCrítica (9.9)1.7%—Microsoft Azure Service BUS7/8/20267/8/2026
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
AnalizadaCrítica (9.9)0.82%—Microsoft Azure Active Directory7/8/20267/8/2026
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Azure Cosmos DB30/7/20264/8/2026
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.5)0.97%—Microsoft Azure Portal24/7/202629/7/2026
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
AnalizadaCrítica (9.8)0.86%—Microsoft Azure APP Service FOR Linux24/7/20266/8/2026
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Azure Kubernetes Service24/7/202629/7/2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.92%—Microsoft Azure KEY Vault24/7/20267/8/2026
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.92%—Microsoft Azure DNS24/7/20267/8/2026
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.55%—Microsoft Azure AI Search24/7/202629/7/2026
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.9)0.79%—Microsoft Azure RED HAT Openshift24/7/20267/8/2026
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.2)0.70%—Microsoft Azure API Management24/7/202617/8/2026
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Pendiente de análisisCrítica (9.8)0.43%💥 PoCMicrosoft Azure API ManagementAI21/7/20265/10/2026
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup disabled at the UI level. In other words,…
AnalizadaMedia (6.5)0.64%—Microsoft Azure Cyclecloud14/7/202622/7/2026
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Azure Cyclecloud14/7/202622/7/2026
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft Azure Active Directory14/7/202624/7/2026
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.7%—Microsoft .net FrameworkMicrosoft Azure Active Directory14/7/202624/7/2026
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (8.2)0.52%💥 PoCMicrosoft Azure Spring Cloud14/7/202624/7/2026
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
ModificadaAlta (8.8)0.50%—Microsoft Azure Connected Machine Agent14/7/202618/8/2026
Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
Pendiente de análisisMedia (6.9)0.47%💥 PoCMicrosoft Azure Blob StorageAI3/7/20266/7/2026
The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container.
AnalizadaAlta (8.8)0.78%—Microsoft Azure Openai2/7/20267/7/2026
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.70%—Microsoft Azure Synapse2/7/20267/7/2026
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
AplazadaAlta (8.2)0.20%—OpenprojectAIMicrosoft OnedriveAIMicrosoft SharepointAIMicrosoft Azure ADAI26/6/202629/6/2026
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key storage.<id>.httpx_access_token, repopulated continuously by an hourly cron and…
AnalizadaAlta (8.8)0.91%—Microsoft Azure Synapse19/6/202629/6/2026
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Azure Active Directory19/6/202624/6/2026
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
Orbitaley — Vulnerabilidades